Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-41599 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The system service has a vulnerability that causes incorrect return values. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-41596 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components. | ||
| CVE-2022-41591 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2022 | The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other system files. | ||
| CVE-2021-46856 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2022 | The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-44561 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction. | ||
| CVE-2022-44557 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-44555 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable. | ||
| CVE-2022-44554 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device. | ||
| CVE-2022-44552 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The lock screen module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-44550 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-44549 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality. | ||
| CVE-2022-44547 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability. | ||
| CVE-2022-44546 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Successful exploitation of this vulnerability may cause a system restart. | ||
| CVE-2021-46852 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-44556 | Hig | 0.49 | 7.5 | 0.00 | Nov 8, 2022 | Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2022-41589 | Hig | 0.49 | 7.5 | 0.01 | Oct 14, 2022 | The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful exploitation of this vulnerability affects system services and device availability. | ||
| CVE-2022-41588 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The home screen module has a vulnerability in service logic processing.Successful exploitation of this vulnerability may affect data integrity. | ||
| CVE-2022-41586 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-41583 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module. | ||
| CVE-2022-41582 | Hig | 0.49 | 7.5 | 0.01 | Oct 14, 2022 | The security module has configuration defects.Successful exploitation of this vulnerability may affect system availability. |
- risk 0.49cvss 7.5epss 0.00
The system service has a vulnerability that causes incorrect return values. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components.
- risk 0.49cvss 7.5epss 0.01
The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other system files.
- risk 0.49cvss 7.5epss 0.01
The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.
- risk 0.49cvss 7.5epss 0.00
The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.
- risk 0.49cvss 7.5epss 0.00
The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.
- risk 0.49cvss 7.5epss 0.00
The lock screen module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.
- risk 0.49cvss 7.5epss 0.00
The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability.
- risk 0.49cvss 7.5epss 0.00
The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Successful exploitation of this vulnerability may cause a system restart.
- risk 0.49cvss 7.5epss 0.00
The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.01
The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful exploitation of this vulnerability affects system services and device availability.
- risk 0.49cvss 7.5epss 0.00
The home screen module has a vulnerability in service logic processing.Successful exploitation of this vulnerability may affect data integrity.
- risk 0.49cvss 7.5epss 0.00
The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module.
- risk 0.49cvss 7.5epss 0.01
The security module has configuration defects.Successful exploitation of this vulnerability may affect system availability.
Page 22 of 54